If you have performed the data discovery exercise laid out in the last GDPR Step-by-Step blog, you will now have a bunch of data with only limited context. For data to become information, you need to provide the appropriate context, which in GDPR terms, is in the form of a ‘business process’.
Every department has at least one, and likely several individual processes that handle personal data, each in their own way. All of these need to be defined as they will each require a determination of their lawful basis for processing, and will correspond directly to the record keeping requirements of Article 30.
Continue reading “GDPR Compliance Step-by-Step: Part 3 – Process Mapping”